pypi package report

Is Products.CMFPlone safe?

7 known vulnerabilities, worst severity HIGH.

cvss
7.5

how bad it is if exploited, out of 10

epss
2.0%

chance of exploitation in the next 30 days

xyz score
4.1

CyberXYZ composite, out of 10

fig. 01 — GHSA-984m-rj28-8c6x, the advisory selected below

// advisories

GHSA-984m-rj28-8c6x

HIGHCVE-2015-7315

Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to add a new member to a Plone site with registration enabled, without acknowledgment of site administrator.

Affected
>= 3.3.0, < 4.3.6, >= 5.0a1, < 5.0rc2
Fixed in
4.3.7
Weakness
CWE-284
Published
2022-05-17
Source
github

GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereference


// ai model usage

No published models are known to use this package.


Checked 2026-09-22 at 00:49 UTC. The most recent advisory here was published 2022-05-17. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is Products.CMFPlone safe? pypi package security report | CyberXYZ